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Period for Reply 

A SHORTENED STATUTORY PERIOD FOR REPLY IS SET TO EXPIRE 3 MONTH(S) FROM 
THE MAILING DATE OF THIS COMMUNICATION. 

• Extensions of time may be available under the provisions of 37 CFR 1 .136(a). In no event, however, may a reply be timely filed 
after SIX (6) MONTHS from the mailing date of this communication. 

- If the period for reply specified above is less than thirty (30) days, a reply within the statutory minimum of thirty (30) days will be considered timely. 

- If NO period for reply is specified above, the maximum statutory period will apply and will expire SIX (6) MONTHS from the mailing date of this communication. 

- Failure to reply within the set or extended period for reply will, by statute, cause the application to become ABANDONED (35 U.S.C. § 1 33). 
Any reply received by the Office later than three months after the mailing date of this communication, even if timely filed, may reduce any 
earned patent term adjustment. See 37 CFR 1.704(b). 

Status 

1)^ Responsive to communication(s) filed on 29 April 2005 . 
2a)^ This action is FINAL. 2b)D This action is non-final. 

3) D Since this application is in condition for allowance except for formal matters, prosecution as to the merits is 

closed in accordance with the practice under Ex parte Quay/e, 1935 CD. 1 1 , 453 O.G. 213. 

Disposition of Claims 

4) S Claim(s) 1-12.14.15 and 40-48 is/are pending in the application. 

4a) Of the above claim(s) is/are withdrawn from consideration. 

5) D Claim(s) is/are allowed. 

6) E3 Claim(s) 1-12. 14. 15 and 40-48 is/are rejected. 

7) D Claim(s) is/are objected to. 

8) D Claim(s) are subject to restriction and/or election requirement. 

Application Papers 

9) D The specification is objected to by the Examiner. 

10) D The drawing(s) filed on is/are: a)D accepted or b)D objected to by the Examiner. 

Applicant may not request that any objection to the drawing(s) be held in abeyance. See 37 CFR 1.85(a). 
Replacement drawing sheet(s) including the correction is required if the drawing(s) is objected to. See 37 CFR 1.121(d). 

11) D The oath or declaration is objected to by the Examiner. Note the attached Office Action or form PTO-152. 

Priority under 35 U.S.C. § 119 

12) Q Acknowledgment is made of a claim for foreign priority under 35 U.S.C. § 1 19(a)-(d) or (f). 
a)D All b)D Some * c)Q None of: 

1 Certified copies of the priority documents have been received. 

2. D Certified copies of the priority documents have been received in Application No. . 

3. D Copies of the certified copies of the priority documents have been received in this National Stage 

application from the International Bureau (PCT Rule 17.2(a)). 
* See the attached detailed Office action for a list of the certified copies not received. 



Attachment(s) 

1) K Notice of References Cited (PTO-892) 

2) d Notice of Draftsperson's Patent Drawing Review (PTO-948) 

3) □ Information Disclosure Statement(s) (PTO-1449 or PTO/SB/08) 

Paper No(s)/Mail Date . 



4) CD Interview Summary (PTO-413) 

Paper No(s)/Mail Date. . 

5) □ Notice of Informal Patent Application (PTO-152) 

6) □ Other: . 



U.S. Patent and Trademark Office 
PTOL-326 (Rev. 1-04) 



Office Action Summary 



Part of Paper No./Mail Date 20050512 



Application/Control Number: 09/827,451 
Art Unit: 2137 



Page 2 



DETAILED ACTION 

1. Claims 1-12, 14-15, 40-48 are pending. 

2. Amendment filed 04/29/2005 has been received and 
considered. 

Claim Objections 

3. Claim 2 recites "The method of claim 2" which should read 
"The method of claim 1." Appropriate change is required. 

Claim Rejections - 35 USC §103 

4. The following is a quotation of 35 U.S.C. 103(a) which 
forms the basis for all obviousness rejections set forth in this 
Office action: 

(a) A patent may not be obtained though the invention is not identically 
disclosed or described as set forth in section 102 of this title, if the 
differences between the subject matter sought to be patented and the prior 
art are such that the subject matter as a whole would have been obvious at 
the time the invention was made to a person having ordinary skill in the 
art to which said subject matter pertains. Patentability shall not be 
negatived by the manner in which the invention was made. 

5. Claims 1-4, 8, 12, 14-15, and 40-48 are rejected under 35 
U.S.C. 103(a) as being unpatentable over Tingley et al (U.S. 
6,708,211) and further in view of Evoy (U.S. 6,591,377) and 
further in view of Brain (How Stuff Works) . 

As per claims 1, 14-15 Tingley et al discloses a method of 
detecting states that are activated by a computer unit 
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comprising: checking a set of values in a memory area of the 
computer unit or in a proprietary file stored within the 
computer unit, with each set of values correspond to a state 
activated by the computer unit, and capturing each set of values 
to determine each state activated by the computer unit (see 
column 1 line 62 through column 2 line 1) and alerting when a 
modification has been made (see column 9 line 61 through column 
10 line 27) . 

Tingley et al fails to disclose the checking includes 
calculating a maximum base count for entries in a defined 
registry segment for determining unauthorized behavior a signal 
file that includes initial registry information, determining if 
the registry has been modified. 

However, Evoy teaches calculating a maximum base count for 
entries in a defined registry segment for determining 
unauthorized behavior (see column 3 lines 1-15) and the file 
with the registry information (see column 5 lines 31-49) . 

At the time of the invention it would have been obvious to 
a person of ordinary skill in the art to use Evoy' s method of 
determining unauthorized behavior in the method of Tingley et 
al. 
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Motivation to do so would have been to allow a user to 
determine if a particular program is running compared to a 
previous time (see Evoy column 3 lines 4-15) . 

The modified Tingley and Evoy system fails to disclose the 
signal file including boot up files and directories and files 
and directories that initiate third part programs. 

However, Brain teaches why these files and directories 
should be modified (see page 2) , 

At the time of the invention it would have been obvious to 
a person of ordinary skill in the art to monitor Brain's files 
using the modified Tingley and Evoy monitoring system. 

Motivation to do so would have been to protect the system 
from viruses (see page 1) . 

As per claims 2-3, the modified Tingley, Evoy and Brain 
system discloses initiating a parallel registry segment thread 
to collect registry data (see Tingley et al column 7 lines 6- 
14) . 

As per claims 4, 8, the modified Tingley, Evoy and Brain 
system discloses initiation a parallel operating system segment 
thread and a polling thread (see Tingley et al column 6 lines 
40-46) . 
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As per claim 12, the modified Tingley, Evoy and Brain 
system discloses detecting for an unauthorized modification (see 
Evoy column 3 lines 1-15) . 

As per claims 40-48, the modified Tingley, Evoy and Brain 
system discloses restoring the system to an original state (see 
column 7 lines 27-46) . 

6. Claims 5, 10 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over the modified Tingley, Evoy and Brain system as 
applied to claims 4, 8 above, and further in view of Glowny et 
al (U.S. 5,491, 791) . 

As per claims 5, 10 the modified Tingley, Evoy and Brain 
system fails to disclose analyzing at least one of an operating 
system directory structure, "root" and all directories and sub- 
directories, and loading configuration data into memory. 

However, Glowny et al teaches these tasks (see column 3 
lines 21-30 where it is clear that a virus scanner scans all 
files and therefore all directories) . 

At the time of the invention it would have been obvious to 
a person of ordinary skill in the art to use Glowny et al' s 
analyzing, scanning and loading in the modified Tingley, Evoy 
and Brain system. 
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Motivation to do so would have been to allow for scanning 
to be more readily performed (see Glowny et al column 3 lines 
21-30) . 

7. Claims 6, 9, 11 are rejected under 35 U.S.C. 103(a) as 
being unpatentable over the modified Tingley, Evoy and Brain 
system as applied to claims 1, 8 above, and further in view of 
Brooks et al (U.S. 6,047,312). 

As per claim 6, the modified Tingley, Evoy and Brain system 
fails to disclose initiating a parallel third party segment 
thread. 

However, Brooks et al teaches initiating a third party 
segment thread (see Brooks et al column 8 lines 34-56) . 

At the time of the invention it would have been obvious to 
a person of ordinary skill in the art to use Brooks et al's 
method of a parallel third party thread in the modified Tingley, 
Evoy and Brain system. 

Motivation to do so would have been to obtain information 
on a third party (see Brooks et al column 8 lines 34-56) . 

As per claim 9, 11, the modified Tingley, Evoy, Brain and 
Brooks et al system discloses loading configuration data and 
third party start up information (see Brooks et al column 8 
lines 43-56 where the registry information is the configuration 
data and start up information) . 
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8. Claim 7 is rejected under 35 U.S.C. 103(a) as being 
unpatentable over the modified Tingley et al, Evoy, Brain and 
Brooks et al system as applied to claim 6 above, and further in 
view of Glowny et al (U.S. 5,491,791). 

As per claim 7 the modified Tingley et al, Evoy, Brain and 
Brooks et al system fails to disclose analyzing at least one of 
scanning all third party start up and initiation files. 

However, Glowny et al teaches these tasks (see column 3 
lines 21-30 where it is clear that a virus scanner scans all 
files and therefore all directories) . 

At the time of the invention it would have been obvious to 
a person of ordinary skill in the art to use Glowny et al's 
analyzing, scanning and loading in the modified Tingley et al, 
Evoy, Brain and Brooks et al system. 

Motivation to do so would have been to allow for scanning 
to be more readily performed (see Glowny et al column 3 lines 
21-30) . 

Response to Arguments 

9. Applicant's arguments, with respect to the prior art 
rejections, towards claims 1-12, 14-15, have been considered but 
are moot in view of the new ground (s) of rejection. 
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10, Applicant's arguments filed 04/29/2005 have been fully 
considered but they are not persuasive. With regard to 
Applicant's arguments that the combinations would require a 
substantial reconstruction and redesign of the primary reference 
and does not provide and systems, methods, etc to permit the 
systems to work together, Applicant's specification gives what 
one of ordinary skill in the art at the time of the invention 
would need to produce Applicant's invention and in the 
specification Applicant is silent as to how the elements of the 
invention work together. It is therefore improper to argue one 
of ordinary skill in the art at the time of the invention would 
require systems, methods, etc explaining how the elements work 
together in the combined references. 

Conclusion 

11. The prior art made of record and not relied upon is 
considered pertinent to applicant's disclosure. Breggin (US 
6560776 Bl) discloses a method of software verification, Sobel 
(US 6785818 Bl) discloses a method of monitoring the registry, 
and Hodges (US 6035423 A) discloses a method of automatic 
updating. 

Any inquiry concerning this communication or earlier ■ 
communications from the examiner should be directed to Michael 
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Pyzocha whose telephone number is (571) 272-3875. The examiner 
can normally be reached on 7:00am - 4:30pm first Fridays of the 
bi-week off. 

If attempts to reach the examiner by telephone are 
unsuccessful, the examiner's supervisor, Andrew Caldwell can be 
reached on (571) 272-3868. The fax phone number for the 
organization where this application or proceeding is assigned is 
703-872-9306. 

Information regarding the status of an application may be 
obtained from the Patent Application Information Retrieval 
(PAIR) system. Status information for published applications 
may be obtained from either Private PAIR or Public PAIR. Status 
information for unpublished applications is available through 
Private PAIR only. For more information about the PAIR system, 
see http://pair-direct.uspto.gov. Should you have questions on 
access to the Private PAIR system, contact the Electronic 
Business Center (EBC) at 866-217-9197 (toll-free) . 



MJP 




